IPDebrief

51.195.215.17

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 51.195.215.17/32

Classification: Moderate Risk / Hosting Infrastructure

Date: Current Analysis

Target: 51.195.215.17 (51.195.215.0/24 subnet)

---

## Executive Summary

IP 51.195.215.17 is a moderate-risk (risk score 40/100) hosting infrastructure IP associated with OVH SAS (ASN 16276) in London, United Kingdom. The address resolves to proxy-uk009-san17.ahrefs.net, indicating use by Ahrefs Pte Ltd. While the IP itself shows no direct threat indicators, it operates within a high-abuse density subnet (0.8047 abuse density) where 206 of 256 sibling IPs are classified as threats. No services are currently exposed on this address (firewalled/no services detected).

---

## Ownership & Infrastructure

AttributeValue
**Organization**Ahrefs Pte Ltd Dmytro
**ASN**16276 (OVH SAS)
**Location**London, England, GB
**CIDR Block**51.195.0.0/16
**Network Role**Hosting Infrastructure
**DNS Hostname**proxy-uk009-san17.ahrefs.net

The IP is registered to OVH hosting infrastructure with no evidence of cloud, CDN, VPN, or proxy operations. The control plane shows the IP is listed on 1 of 8 DNSBLs, with operator classification marked as "Minimal."

---

## Threat Assessment

Direct Threat Indicators: None detected

Risk Context: The IP's moderate risk score (40) is elevated relative to the subnet's overall risk profile. The 51.195.215.0/24 subnet shows 15 medium-risk neighbors and 0 high-risk neighbors among 100 sampled peers.

---

## Observation History

Signal persistence analysis reveals:

---

## Relationship Graph

44 relationships identified, primarily network-level associations with OVH infrastructure (OVH_282347345). No organizational or certificate-level correlations detected. The strong network association indicates legitimate hosting infrastructure rather than compromised endpoint.

---

## Recommended Actions

SOC Analyst Recommendations:

1. Allow with Monitoring: No blocking recommended. The IP resolves to legitimate ahrefs.net infrastructure.

2. Network Context Review: Monitor traffic patterns given the high-abuse subnet environment (0.8047 abuse density). Unusual traffic volumes may warrant investigation.

3. DNSBL Monitoring: One DNSBL listing detected. Verify if listings are false positives or indicate specific policy violations.

4. Subnet Awareness: The 51.195.215.0/24 subnet contains 206 threat-classified siblings. Be aware that other addresses in this /24 may be malicious.

5. Firewall Rules: No immediate blocking rules recommended. Standard monitoring policies apply.

---

Intelligence Confidence: Moderate

Data Sources: 2 geo sources, 8 DNSBL lists, 1 threat observation

Classification Flags: Hosting infrastructure, high-abuse neighborhood, minimal operator risk

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom
RegionENG
CityLondon
TimezoneEurope/London
Latitude51.51
Longitude-0.13

๐Ÿข Ownership & Registration

OrganizationAhrefs Pte Ltd Dmytro
ASNAS16276
Network Nameโ€”
CIDR Blockโ€”
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRproxy-uk009-san17.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-uk009-san17.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
39%
23
routing
13%
11
services
8%
11
ownership
24%
23
reputation
31%
13
geolocation
25%
22
Overall23%913
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-22 15:19:57 UTC
Last Seen2026-06-28 19:54:01 UTC
Profile Built2026-06-29 07:57:55 UTC
Data FreshnessLive
Signal Types19
Total Observations22
๐Ÿ” 19 signal types ยท 22 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.